Live data from Hacker News

Hetzner Servers Compromised

wiki.hetzner.de

11–20 of 133 posts

Re: Hetzner Servers Compromised

#11
Sigh, another hosting provider hack. As if Linode and OVH are not enough. This is the reason why we use full disk encryption, where we enter the key manually during boot. This way we're protected against many types of hosting provider hacks.

Re: Hetzner Servers Compromised

#13
post #2

Full text of the email sent to cutomers: Dear Client At the end of last week, Hetzner technicians discovered a "backdoor" in one of our internal monitoring systems (Nagios). An investigation was launched immediately and showed that the administration interface for dedicated root servers (Robot) had also been affected. Current findings would suggest that fragments of our client database had been copied externally. As…

I don't understand, are they saying the backdoor might be because of the Nagios software or because something has implanted itself into the Nagios software?

Re: Hetzner Servers Compromised

#14
Several events with Linode, now Hetzner. These are relatively "premier," high-quality hosting companies, you can count on thousands and thousands of companies to pay even less attention.

Yet every time, the discussion is only about one specific company, without seeing any broader pattern.

When are we ever going to draw the conclusion that popular hosting companies (and, actually related, facilities like RubyGems) are especially attractive targets, and that the approach of waiting for an exploit and then shaming the targeted company is not an effective way of getting better security?

Re: Hetzner Servers Compromised

#16
post #2

Full text of the email sent to cutomers: Dear Client At the end of last week, Hetzner technicians discovered a "backdoor" in one of our internal monitoring systems (Nagios). An investigation was launched immediately and showed that the administration interface for dedicated root servers (Robot) had also been affected. Current findings would suggest that fragments of our client database had been copied externally. As…

I am not a Hetzner customer, but the comment about Nagios perked up my ears. I work with some clients who have Nagios running in their environment, and I'm wondering if there is an exploit in Nagios or if it's just a coincidence that this was where they noticed the infection?

Re: Hetzner Servers Compromised

#17

Sigh, another hosting provider hack. As if Linode and OVH are not enough. This is the reason why we use full disk encryption, where we enter the key manually during boot. This way we're protected against many types of hosting provider hacks.

What kind of effect does this have on your I/O performance?

Re: Hetzner Servers Compromised

#18

Sigh, another hosting provider hack. As if Linode and OVH are not enough. This is the reason why we use full disk encryption, where we enter the key manually during boot. This way we're protected against many types of hosting provider hacks.

What types of hacks does that protect you from exactly, considering you don't have physical access and can't even see the hardware?

Re: Hetzner Servers Compromised

#19
post #14

Several events with Linode, now Hetzner. These are relatively "premier," high-quality hosting companies, you can count on thousands and thousands of companies to pay even less attention. Yet every time, the discussion is only about one specific company, without seeing any broader pattern. When are we ever going to draw the conclusion that popular hosting companies (and, actually related, facilities like RubyGems) are…

Apply Occam's Razor. The simplest speculation is an internal breach. All the procedure in the world won't save you from that.

Re: Hetzner Servers Compromised

#20
post #17

Sigh, another hosting provider hack. As if Linode and OVH are not enough. This is the reason why we use full disk encryption, where we enter the key manually during boot. This way we're protected against many types of hosting provider hacks.

What kind of effect does this have on your I/O performance?

Minor. It costs more CPU because of encryption/decryption. But our servers have so much CPU power, and our workload is mostly dependent on disk I/O throughput, so enabling encryption is almost free.
Post reply on HN